Lesson 3: Layers of Defense Flashcards

(17 cards)

1
Q

What built-in security features does macOS have for malware?

A

macOS prevents malware from running and remediates malware that has executed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does Gatekeeper help prevent malware?

A

By only allowing software from identified developers to be opened.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What ensures safety of apps in the App Store?

A

All App Store apps are reviewed and signed by Apple.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Apple app notarization?

A

A service by Apple that automatically scans non–App Store software for known malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is notarization the same as App Store review?

A

No, it’s a separate process for software distributed outside the App Store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can Jamf Pro control Gatekeeper and App Store settings?

A

Yes, Jamf Pro can restrict these settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can the Gatekeeper bypass shortcut be restricted?

A

Yes, the control-click bypass can be restricted by Jamf Pro.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is XProtect in macOS?

A

A built-in tool that provides malware remediation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does XProtect work?

A

It detects and blocks execution of known malware automatically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Jamf Protect used for?

A

Additional malware remediation and endpoint threat prevention.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does threat prevention block known malware?

A

It blocks processes matching known threats and quarantines the associated file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does System Integrity Protection (SIP) do?

A

It adds restrictions to the root user and protects system-critical directories.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Is SIP enabled by default?

A

Yes, SIP is enabled by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which directories are protected by SIP?

A

/System, /usr, /bin, /sbin, /var, and pre-installed macOS apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does Gatekeeper help prevent malware?

A

Only apps and packages signed by identified developers can be opened.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Apple app notarization?

A

Notarization is a service by Apple that allows developers who plan to distribute their software outside the App Store to submit their code to be scanned for known malware.

17
Q

How does threat prevention block known malware?

A

Processes that match any known threats in the Jamf Protect threat database are blocked and associated files are quarantined.